NIST releases Transit Cybersecurity Framework Community Profile

Image credit: UTA

The National Institute of Standards and Technology (NIST) National Cybersecurity Center of Excellence (NCCoE) has released the Transit Cybersecurity Framework (CSF) Community Profile. The CSF is a voluntary, risk-based resource to help transit agencies strengthen cybersecurity preparedness and resilience, especially as cyberattacks on transit agencies become more frequent and severe.

The NCCoE will host a virtual event on Tuesday, September 1, 2026 at 2:00 P.M. EDT to enable transit operators to share their perspectives on the Transit Profile and discuss how transit agencies can use it to strengthen cybersecurity and support safe, reliable, and resilient transit operations.

Today’s transit systems rely extensively on technology solutions – both information technologies (IT) to manage the systems and resources as well as operational technologies (OT) to directly support operational requirements. The transit industry has experienced an increase in cyberattacks in both frequency and severity in recent years. This increase underscores the need for robust and standardized cybersecurity measures and proactive strategies to mitigate the risk of these attacks. The NCCoE worked in collaboration with industry and federal agencies to create a CSF Community Profile to help transit agencies protect their most critical operations.

A Community of Interest (COI) is a group of professionals and advisors who share business insights, technical expertise, challenges, and perspectives to guide NCCoE projects. COIs often include experts, innovators, and everyday users of cybersecurity and privacy technologies.

Source: USDOT